usbsafelyremove.exe

USBSafelyRemove

Crystal Rich, Ltd

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘USB Safely Remove’.
Publisher:
Crystal Rich, Ltd  (signed and verified)

Product:
USBSafelyRemove

Description:
Safely Remove A Device In One Click

Version:
4.0.7.750

MD5:
936ea806cbd5f168dfca5f53e123fae6

SHA-1:
20ab99638611366a98b2f84007834e423690bb6d

SHA-256:
14f64d16454b10bae1b4562c2e121e203f02a19bed015b53b1355dae591b7fa2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/16/2024 5:46:49 AM UTC  (today)

File size:
1.1 MB (1,106,704 bytes)

Product version:
4.0.7.750

Copyright:
Copyright © 2004-2008 by SafelyRemove.com

File type:
Executable application (Win32 EXE)

Language:
English (United Kingdom)

Common path:
C:\Program Files\usb safely remove\usbsafelyremove.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
11/23/2008 4:00:00 PM

Valid to:
11/24/2009 3:59:59 PM

Subject:
CN="Crystal Rich, Ltd", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Crystal Rich, Ltd", L=Saint Petersburg, S=Saint Petersburg, C=RU

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
26B48085B616B9641F205166660DF73C

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:r5x/SEc9Ms04+l1snVW5b9oIw3RwelaIbkQmXVmZd4ZFi:rDaEc9nqsnVSb9oVcwmhi

Entry address:
0x1000

Entry point:
68, 01, 60, 67, 00, E8, 01, 00, 00, 00, C3, C3, 93, 62, 43, FC, A3, D6, D9, E5, 9E, A1, 52, 3B, 0D, 38, 48, 9E, 8C, D5, 5D, 15, EC, 40, 53, 6C, 52, 7C, C9, 32, C8, E2, CC, E8, E0, C9, B5, 49, 8C, EC, EA, 17, C5, 07, 8F, 26, 98, DB, 20, C1, BE, D2, 53, 4D, 3D, FC, 0D, B7, 05, 15, C8, CA, 83, 33, EB, 6A, 74, 41, 9A, 52, 1A, B5, 61, E7, 5F, 37, 62, CF, BA, DE, 74, 04, E9, 70, 84, 39, 37, 0F, 91, 02, 93, F3, 29, 11, 3E, 92, 3F, 95, 7D, 55, 96, AF, 6B, EF, 0C, B1, FA, DC, 8E, 6A, 00, CF, FE, 87, FA, 67, 3C, 32...
 
[+]

Entropy:
7.9094

Packer / compiler:
ASProtect v1.2x (New Strain)

Code size:
1.6 MB (1,660,928 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
USB Safely Remove

Command:
C:\Program Files\usb safely remove\usbsafelyremove.exe \startup


Scan usbsafelyremove.exe - Powered by Reason Core Security